iwe all kinda knew Bouzy was taking pish in his press release right?

but hot-dam >> email and IP address, phone number, gender, bcrypt hashed password, 2FA secret and backup code and the code that can be immediately used to reset the password all exposed

the vulnerable APIs was requested organically as a natural part of using the service as it was intended, Spoutible almost certainly won't be able to fully identify abuse of it

troyhunt.com/how-spoutibles-le

Spoutible’s API coughed up passwords, 2FA info, and tokens that could let attackers take over anyone’s account

theverge.com/2024/2/5/24061997

Follow

bouzy will more than likely use this line

"this isn’t entirely uncommon, as seen in similar data-scraping incidents on platforms like Facebook and Trello"

when he tries to spin the whole thing to his followers being the spn-doctor master manipulator he is

Sign in to participate in the conversation

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.